Index: db-derby-10.11.1.1-src/java/engine/org/apache/derby/iapi/types/SqlXmlUtil.java =================================================================== --- java/engine/org/apache/derby/iapi/types/SqlXmlUtil.java 2015/07/16 23:30:22 1691460 +++ java/engine/org/apache/derby/iapi/types/SqlXmlUtil.java 2015/07/17 00:13:38 1691461 @@ -198,6 +198,13 @@ dBF.setValidating(false); dBF.setNamespaceAware(true); + if ( System.getSecurityManager() == null ) + { + dBF.setFeature( XMLConstants.FEATURE_SECURE_PROCESSING, true ); + dBF.setFeature( + "http://xml.org/sax/features/external-general-entities", false ); + } + // Load document builder that can be used for parsing XML. dBuilder = dBF.newDocumentBuilder(); dBuilder.setErrorHandler(new XMLErrorHandler());